DIAGNOSTIC PLAYBOOK

From, Reply-To and Return-Path point to different places

These headers serve different purposes: visible authorship, reply destination and bounce routing. A mismatch may be intentional, but it needs context when investigating authentication or suspicious replies.

HealthCheck Email editorial team · · Examples are illustrative

How to investigate

  1. Record each address separately and identify which one is relevant to the problem.
  2. For DMARC, compare the visible From domain with the authenticated identities rather than Reply-To.
  3. For unexpected replies or bounces, inspect the sending application's reply and envelope configuration.

What this looks like

ILLUSTRATIVE EXAMPLE

A support platform displays your business From address, routes replies to a ticket address and handles bounces on a vendor domain. The fields need not be identical.

A mistake to avoid

Matching display names do not prove matching domains. Inspect the full addresses when reviewing unexpected destinations.

Keep the result in context

Inspect the original raw message rather than a forwarded screenshot. Headers can contain private addresses, message identifiers and routing information, so redact a separate copy before sharing. Give the most weight to results added by your own trusted receiving infrastructure.

Take the next step

Use the related check to gather evidence, then compare it with the affected message or service. Keep the result and time with your notes so a later change can be distinguished from the original problem.

Sources and further reading

The protocol references below explain the underlying behavior. Your sending or DNS provider supplies the account-specific settings for its service.